A security research MCP server for testing tool call safety with deterministic policies like allowlists, path boundary enforcement, SSRF prevention, output redaction, and prompt injection detection, without requiring external LLMs or API keys.
MCP server for security bug-finding that proves every finding by running exploits, enabling agents to verify changes and find bugs with execution-based evidence.
An LLM-powered vulnerability auditor for MCP servers that catches semantically-equivalent attacks by using a local LLM grounded by retrieval against known attack patterns.
A deliberately dishonest MCP server that measures an agent system's honesty via deterministic, rule-driven lies across five modes, recording ground truth for scoring.